All Categories → Security → infosec

Top 308 infosec open source projects

Personal Security Checklist
Personal security checklist for securing your devices and accounts.
Isthislegit
Dashboard to collect, analyze, and respond to reported phishing emails.
Credsleaker
Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it via an HTTP request.
Keydecoder
KeyDecoder app lets you use your smartphone or tablet to decode your mechanical keys in seconds.
Autosqli
An automatic SQL Injection tool which takes advantage of ~DorkNet~ Googler, Ddgr, WhatWaf and sqlmap.
Sec Admin
分布式资产安全扫描核心管理系统(弱口令扫描,漏洞扫描)
Ronin
Ronin is a Ruby platform for vulnerability research and exploit development. Ronin allows for the rapid development and distribution of code, Exploits or Payloads, Scanners, etc, via Repositories.
Contact.sh
An OSINT tool to find contacts in order to report security vulnerabilities.
Can I Take Over Xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
Pwdb Public
A collection of all the data i could extract from 1 billion leaked credentials from internet.
Secure Desktop
Anti-keylogger/anti-rat application for Windows
Hawkeye
Hawkeye filesystem analysis tool
Qsfuzz
qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.
Pockint
A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️
Sbt Dependency Check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). 🌈
Crithit
Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
Miniprint
A medium interaction printer honeypot 🍯
Yar
Yar is a tool for plunderin' organizations, users and/or repositories.
Securityadvisories
🔐 Security advisories as a simple composer exclusion list, updated daily
Umbrella android
Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with a kidnap. Umbrella has best practice guides in over 40 topics in multiple languages. Used daily by people working in high risk countries - journalists, activists, diplomats, business travelers etc.
Smogcloud
Find cloud assets that no one wants exposed 🔎 ☁️
Dymerge
🔓 A dynamic dictionary merger for successful dictionary based attacks.
Hackthebox
Notes Taken for HTB Machines & InfoSec Community.
Asnlookup
Leverage ASN to look up IP addresses (IPv4 & IPv6) owned by a specific organization for reconnaissance purposes, then run port scanning on it.
Python Honeypot
OWASP Honeypot, Automated Deception Framework.
Slack Watchman
Monitoring your Slack workspaces for sensitive information
Linkfinder
A python script that finds endpoints in JavaScript files
Karma
Find leaked emails with your passwords
Urlcrazy
Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.
Amitt framework
Repo replaced by cogsec-collaborative/AMITT
Offensive Dockerfiles
Offensive tools as Dockerfiles. Lightweight & Ready to go
Proof Of Concepts
A little collection of fun and creative proof of concepts to demonstrate the potential impact of a security vulnerability.
Myriam
A vulnerable iOS App with Security Challenges for the Security Researcher inside you.
Wincmdfu
Windows one line commands that make life easier, shortcuts and command line fu.
Pyiris Backdoor
PyIris-backdoor is a modular, stealthy and flexible remote-access-toolkit written completely in python used to command and control other systems. It is now in the beta stage, possibly perpetually. There are bugs still present in the framework, feel free to contribute or help me out with this project its still under active development >_>
Binsnitch
Detect silent (unwanted) changes to files on your system
Breach.tw
A service that can track data breaches like "Have I Been Pwned", but it is specific for Taiwan.
Autosetup
Auto setup is a bash script compatible with Debian based distributions to install and setup necessary programs.
Kurukshetra
Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.
Jsonp
jsonp is a Burp Extension which attempts to reveal JSONP functionality behind JSON endpoints. This could help reveal cross-site script inclusion vulnerabilities or aid in bypassing content security policies.
Oob Server
A Bind9 server for pentesters to use for Out-of-Band vulnerabilities
Gitlab Watchman
Monitoring GitLab for sensitive data shared publicly
Chatter
internet monitoring osint telegram bot for windows
Spaces Finder
A tool to hunt for publicly accessible DigitalOcean Spaces
Defaultcreds Cheat Sheet
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
Goaltdns
A permutation generation tool written in golang
Awesome Cybersecurity Blueteam
💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
Mitmap
📡 A python program to create a fake AP and sniff data.
Phish Collect
Python script to hunt phishing kits
1-60 of 308 infosec projects